exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 29 discussion

Actual exam question from ISC's CISSP
Question #: 29
Topic #: 1
[All CISSP Questions]

An organization recently suffered from a web-application attack that resulted in stolen user session cookie information. The attacker was able to obtain the information when a user's browser executed a script upon visiting a compromised website. What type of attack MOST likely occurred?

  • A. SQL injection (SQLi)
  • B. Extensible Markup Language (XML) external entities
  • C. Cross-Site Scripting (XSS)
  • D. Cross-Site Request Forgery (CSRF)
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ShefAZ
2 months, 1 week ago
Selected Answer: D
browser executed a script upon visiting a compromised websit A Cross-Site Request Forgery (CSRF) attack occurs when a malicious web site, email, blog, instant message, or program tricks an authenticated user's web browser into performing an unwanted action on a trusted site.
upvoted 2 times
...
A1nthem
4 months, 2 weeks ago
Selected Answer: C
XXS: </sript> to load on browser
upvoted 1 times
...
kandegama
10 months, 3 weeks ago
Selected Answer: C
XSS happen on client side. CSRF happening on web server side.therefore Answer is C
upvoted 3 times
jackdryan
10 months ago
C is correct
upvoted 2 times
...
...
Arunlab
1 year, 3 months ago
Ignore my comment. I will go with C
upvoted 1 times
...
Arunlab
1 year, 3 months ago
Answer is D CSRF uses the authentication cookie. Cross site request forgery (CSRF) is a web application security attack that tricks a web browser into executing an unwanted action in an application to which a user is already logged in. The attack is also known as XSRF, Sea Surf or Session Riding.
upvoted 2 times
...
Jamati
1 year, 3 months ago
Selected Answer: C
XSS injects a malicious script into a vulnerable website in order to get a user's session cookies when they visit the compromised website. XSRF/CSRF on the other hand only targets the user directly, it does not compromise any website and does not get session cookies.
upvoted 3 times
...
rootic
1 year, 3 months ago
Selected Answer: C
Definetely C.
upvoted 1 times
...
Eltooth
1 year, 4 months ago
Selected Answer: C
C is correct answer. An attacker can use XSS to send a malicious script to an unsuspecting user. The end user’s browser has no way to know that the script should not be trusted, and will execute the script. Because it thinks the script came from a trusted source, the malicious script can access any cookies, session tokens, or other sensitive information retained by the browser and used with that site. https://owasp.org/www-community/attacks/xss/ https://owasp.org/www-community/attacks/csrf
upvoted 3 times
...
explorer3
1 year, 4 months ago
Selected Answer: C
Correct answer is C - Cross-site script attack The attacker can compromise the session token by using malicious code or programs running at the client-side. The example shows how the attacker could use an XSS attack to steal the session token. If an attacker sends a crafted link to the victim with the malicious JavaScript, when the victim clicks on the link, the JavaScript will run and complete the instructions made by the attacker. The example in figure 3 uses an XSS attack to show the cookie value of the current session; using the same technique it’s possible to create a specific JavaScript code that will send the cookie to the attacker. https://owasp.org/www-community/attacks/Session_hijacking_attack
upvoted 2 times
...
franbarpro
1 year, 5 months ago
Selected Answer: C
Agree with C - If is a scrypt (JavaScript) in the browser. Def XSS.
upvoted 1 times
...
Cww1
1 year, 5 months ago
its C, the stolen session cookie information part of the question is trying to trick you into picking CSRF
upvoted 3 times
...
Toa
1 year, 5 months ago
Answer C https://www.fortinet.com/resources/cyberglossary/cross-site-scripting
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago